Search jobs > New York, NY > Technical architect

Technical Security Architect

Thomson Reuters
New York, New York, United States of America
$173.3K-$321.8K a year
Full-time

Looking forward to advance your career and Upgrade Yourself? We are growing and we are hiring, come join us for a great future and an exciting journey with an Enterprise which has demonstrated business growth year on year with a successful track record of employee satisfaction.

Lead individual Enterprise Security Architect role for complex security functions reducing risk, improving defensive capabilities, and mitigating cyber threats to both Thomson Reuters and its customers.

About the role :

In this opportunity as Technical Security Architect , you will :

Maintain a deep understanding of core public cloud security disciplines, with close attention to developing industry trends in the context of networking, identity, and platform security technologies

Serve as the Cloud Security Lead in the design, implementation, and integration phases of business products and services to meet business security requirements, address corporate risks and exposures in cloud-based solutions

Maintain a deep understanding of capabilities and patterns to controlling access to the public cloud through authentication, authorization, access policy, and secrets management

Collaborate with business and technology peers to understand business goals, use cases for cloud-native deployments or lift-and-shift

Thoroughly interact with DevOps, platform engineering team, Network security engineers, and Identity build and run teams.

Should be able to guide the teams to drive results and maturity

Perform threat modelling on the cloud-based scenarios and able to apply the principles to secure the cloud platforms

Drive security design principles and requirements to enhance ISRMs ability to streamline the implementation of security controls into new and existing solutions

Should be able to enforce the security principles in live scenarios by working closing with landing zone teams

Serve as a cloud security subject matter expert during discussions and meetings with key stakeholders within the business unit and infrastructure teams

Interact with peers, project teams, technical specialists, and other senior members of the company to provide advice on cloud security and identity- related security.

Provide technical security expertise, including communicating security architectural decisions, benefits, risks, and other activities including security requirement definition, and facilitation of security testing and management of residual risk with the product or application teams

Develop and maintain security frameworks, consisting of appropriate controls from NIST CSF, PCI-DSS, HIPAA, and other relevant industry documentation

Authoritatively assess, analyse and recommend security best practices and controls based on TR standard based and industry aligned regulatory requirements specific security controls and guidelines while integrating and onboarding new technologies and platforms within TR DC IT cloud network environments to support various TR initiatives and business objectives - These can be new age digital initiatives such as hybrid / multi-cloud platforms / AI - ML based solutions or technologies in compliance with global data privacy / data protection standards

About you :

You're a fit for the role of Technical Security Architect if your background includes :

Minimum 10+ Years experience in a security-related domain and technologies

Minimum 8+ Years experience in security architecture space

Minimum 5+ Years of Hands-On experience in the cloud security platforms such as AWS, Azure or Google (preferably engineering)

Hands-on capability on Cloud platforms and migrating workloads from Data Center to Cloud Platforms

Should be conversant with most of the Cloud Platform Security domains

Should have good knowledge of security containers and hands-on experience on SecDevOps principles and has a good handle on end-to-end Sec Dev Ops processes.

Good understanding of Technologies such Web Application Firewall, Key Management, Secrets Handling, knowledge on the tools which provide services like Single Sign-On, MFA, enabling data security principles in the cloud platforms.

Etc Technology and hands-on exposure to Active Directory, Palo Alto Prisma, Advanced firewalls, virtual directory services, etc

Bachelor’s degree in Computer Science, Computer Engineering, or related field required

Certification like AWS Security Specialty, Google Cloud Platform Engineer with focus on security, Azure Security, etc are preferred

Technical understanding of cloud-native architecture and engineering best practices

CISSP or equivalent certification are preferred

Has demonstrated experience in

Cyber Security Controls Definition & Solutions Architecture Design based on industry specific and regulatory standards & compliances such as ISO27001, NIST 800-53, PCI-DSS, HIPAA and Data Privacy Standards viz GDPR, CCPA etc

Pre-acquisition / Pre-Onboarding - 3rd Party Integration Risk Assessment & Due Diligence of vendor technologies

Cloud security architecture reviews, across cloud / hybrid / multi-cloud platforms

Design & ensure delivery of high quality cyber security processes and tools across cloud infrastructure covering but not limited to

  • Secure business Process & Applications Integration;
  • 3rd Party Vendor Integration Risk Assessment;
  • Network Security Segmentation & Zoning across environments, regions, VPCs and security groups;
  • Secure Access / Network Connect;
  • Remote Access VPN & Private Links / DirectConnect etc;
  • Perimeter Protection - Layer 4-7 Security WAF / LB / ADDoS and Web / Email / API Gateway;
  • Secure End Points and Secure Workspace; Secure Hosts and Compute Workloads; Containers / Microservices Security;
  • Identity Access Governance; Secure Access for Employees, Vendors & Customers;
  • Data Privacy / Protection Encryption / Anonymization / Tokenization etc;
  • Logging, Auditing and Monitoring; Security Incident Response Management;
  • Cyber Threat Intelligence; Threat Hunting / Threat Management;
  • Insider Threats and Breach Risk Detection and Cyber Forensic;
  • Defensive Security and Engineering;

Vulnerability and Threat Management thereby reducing attack surface improving cyber risk posture of enterprise following Secure Change Configuration management Processes

Authoritatively drive continuous improvements in key cyber defence capabilities by streamlining technology acquisition and deployment, engineering solutions and driving deployment of innovative processes and controls

Designs and executes cyber security plans, activities, and policies that protect Thomson Reuters’ information infrastructure, customer base, and products.

Assists in maturing cyber defense capabilities, enforces organizational security principles and industry recognized best practices, and demonstrates responsible resource management.

Works independently or leads functional project teams to implement security controls, monitor and mitigate threats, tune and optimize security appliances, coordinate with enterprise information services teams, interface with product teams, or other tasks associated with cyber defence and cyber fusion centers.

Understands and have proven experience around cloud and cloud security architectures and related compliances and standards.

The role demands knowledge and experience around cloud security architectures and solutions design, review and risk assessment

LI-LP2

What's in it For You?

You will join our inclusive culture of world-class talent, where we are committed to your personal and professional growth through :

Hybrid Work Model : We’ve adopted a flexible hybrid working environment (2-3 days a week in the office depending on the role) for our office-based roles while delivering a seamless experience that is digitally and physically connected

  • Wellbeing : Comprehensive benefit plans; flexible and supportive benefits for work-life balance : flexible vacation, two company-wide Mental Health Days Off;
  • work from another location for up to a total of 8 weeks in a year, 4 of those weeks can be out of the country and the remaining in the country, Headspace app subscription;

retirement, savings, tuition reimbursement, and employee incentive programs; resources for mental, physical, and financial wellbeing.

Culture : Globally recognized and award-winning reputation for equality, diversity and inclusion, flexibility, work-life balance, and more.

Learning & Development : LinkedIn Learning access; internal Talent Marketplace with opportunities to work on projects cross-company;

Ten Thousand Coffees Thomson Reuters café networking.

Social Impact : Ten employee-driven Business Resource Groups; two paid volunteer days annually; Environmental, Social and Governance (ESG) initiatives for local and global impact.

Purpose Driven Work : We have a superpower that we’ve never talked about with as much pride as we should we are one of the only companies on the planet that helps its customers pursue justice, truth and transparency.

Together, with the professionals and institutions we serve, we help uphold the rule of law, turn the wheels of commerce, catch bad actors, report the facts, and provide trusted, unbiased information to people all over the world.

In the United States, Thomson Reuters offers a comprehensive benefits package to our employees. Our benefit package includes market competitive health, dental, vision, disability, and life insurance programs, as well as a competitive 401k plan with company match.

In addition, Thomson Reuters offers market leading work life benefits with competitive vacation, sick and safe paid time off, paid holidays (including two company mental health days off), parental leave, sabbatical leave.

These benefits meet or exceeds the requirements of paid time off in accordance with any applicable state or municipal laws.

  • Finally, Thomson Reuters offers the following additional benefits : optional hospital, accident and sickness insurance paid 100% by the employee;
  • optional life and AD&D insurance paid 100% by the employee; Flexible Spending and Health Savings Accounts; fitness reimbursement;
  • access to Employee Assistance Program; Group Legal Identity Theft Protection benefit paid 100% by employee; access to 529 Plan;

commuter benefits; Adoption & Surrogacy Assistance; Tuition Reimbursement; and access to Employee Stock Purchase Plan.Thomson Reuters complies with local laws that require upfront disclosure of the expected pay range for a position.

The location(s) for this role include one or more of the following metro locations : Los Angeles, New York City, San Francisco, Washington, DC.

The base compensation range for the role in any of those locations is $173,300 - $321,800. The base compensation range in other locations may vary.

This role may also be eligible for an Annual Bonus based on a combination of enterprise and individual performance. Base pay is positioned within the range based on several factors including an individual’s knowledge, skills and experience with consideration given to internal equity.

Base pay is one part of a comprehensive Total Reward program which also includes flexible and supportive benefits and other wellbeing programs.

Do you want to be part of a team helping re-invent the way knowledge professionals work? How about a team that works every day to create a more transparent, just and inclusive future?

At Thomson Reuters, we’ve been doing just that for almost 160 years. Our industry-leading products and services include highly specialized information-enabled software and tools for legal, tax, accounting and compliance professionals combined with the world’s most global news services Reuters.

We help these professionals do their jobs better, creating more time for them to focus on the things that matter most : advising, advocating, negotiating, governing and informing.

We are powered by the talents of 26,000 employees across more than 70 countries, where everyone has a chance to contribute and grow professionally in flexible work environments that celebrate diversity and inclusion.

At a time when objectivity, accuracy, fairness and transparency are under attack, we consider it our duty to pursue them.

Sound exciting? Join us and help shape the industries that move society forward.

Accessibility

As a global business, we rely on diversity of culture and thought to deliver on our goals. To ensure we can do that, we seek talented, qualified employees in all our operations around the world regardless of race, color, sex / gender, including pregnancy, gender identity and expression, national origin, religion, sexual orientation, disability, age, marital status, citizen status, veteran status, or any other protected classification under applicable law.

Thomson Reuters is proud to be an Equal Employment Opportunity / Affirmative Action Employer providing a drug-free workplace.

18 days ago
Related jobs
Promoted
Thomson Reuters
New York, New York

Provide technical security expertise, including communicating security architectural decisions, benefits, risks, and other activities including security requirement definition, and facilitation of security testing and management of residual risk with the product or application teams. Lead individual...

City National Bank
New York, New York

What you will do Create high-level conceptual and logical security architecture plans, roadmaps and designs for the security technology portfolio Consult, advise or oversee the secure design of key IT system and infrastructure projects to ensure alignment with enterprise security architecture Provid...

Thomson Reuters
New York, New York

Provide technical security expertise, including communicating security architectural decisions, benefits, risks, and other activities including security requirement definition, and facilitation of security testing and management of residual risk with the product or application teams . Lead individua...

City National Bank
New York, New York

What you will do Create high-level conceptual and logical security architecture plans, roadmaps and designs for the security technology portfolio Consult, advise or oversee the secure design of key IT system and infrastructure projects to ensure alignment with enterprise security architecture Provid...

City National Bank
New York, New York

The Information Security Architect has a demonstrated mastery in multiple security and non-security technology platforms, with the ability to both lead and advise on the overall designs and strategies of both security and non-security technologies. WHAT IS THE OPPORTUNITY? The Information Security A...

City National Bank
New York, New York

The Information Security Architect has a demonstrated mastery in multiple security and non-security technology platforms, with the ability to both lead and advise on the overall designs and strategies of both security and non-security technologies. WHAT IS THE OPPORTUNITY? The Information Security A...

Promoted
Boston Consulting Group
New York, New York

As a Lead or Principal Architect, you will collaborate on interdisciplinary teams of designers, engineers, researchers, technical experts, and consultants to develop leading IT concepts and architectural solutions. Ideal candidate requirements given client and contract / portfolio requirements inclu...

Promoted
Sumitomo Mitsui Banking Corporation (SMBC)
New York, New York

Performs as the Subject Matter expert focused on multiple technologies within the Security domains (Security Engineering, IAM, Cloud Security, Data Security, Network Security, Encryption, Privileged Access Management, Federation etc. The Director of Cloud Security Architecture will ensure bank's clo...

Promoted
Equiliem
New York, New York

Assessing security requirements by analyzing business strategies and requirements; researching information security standards; performing system security and vulnerability analyses specific to privileged access; identifying integration issues; and preparing cost estimates. Strong technical backgroun...

Promoted
VirtualVocations
Brooklyn, New York

A company is looking for an Information Systems Security Engineer (ISSE). Key Responsibilities:Maintaining ATO packages and documentation within eMASSReviewing vulnerability scan data and leading vulnerability management effortsSupporting incident response activities and ensuring security incidents ...